meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 12th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 October 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft October 2022 Patches; SAP Patch Day; CISA Chinese State Sponsored Vuln List

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, October 12, 2020 edition of the Sands and Storm Center's Stormcast.

0:08.9

My name is Johannes Ulrich, and today I'm recording from Riyadh, Saudi Arabia.

0:14.5

Today, of course, is Microsoft patched Tuesday, and we got patches for 96-4101 billies, which does include the chromium patches

0:24.3

for Microsoft Edge that actually came out earlier this month, but are included sort of as part

0:31.3

of the set of patches. 13 of the patches are rated critical, 71 important, and one patch is rated as moderate.

0:40.8

But the real news everybody's waiting for, of course, was a patch for Microsoft Exchange,

0:45.9

and, well, that already exploited vulnerability is not being patched this month.

0:52.7

As part of the Exchange Server October 22 security update,

0:57.8

Microsoft states that the October 22 SUs do not include a patch for these vulnerabilities.

1:08.3

So that's CVE 202040 and CVE 2022VE 2022 41082. The post then refers to the

1:18.3

workaround published earlier and a couple of times already updated and states that the patches

1:24.9

will be released when they are ready. So apparently it does take a

1:29.1

bit longer. It's a bit more of a complicated patch. One vulnerability is CVE 224103, a Windows

1:38.5

Com Plus event system service elevation of bridge vulnerability. Well, it's already being exploited and then we do

1:49.1

have another patch CVE 2022 41043, Microsoft Office Information Disclosure vulnerability, not yet

1:58.0

exploited, but already publicly known before the patch was released today.

2:04.6

Also, kind of interest are that there were a number of vulnerabilities in the Windows point-to-point

2:09.5

tunneling protocol that were rated critical and that may lead to code execution.

2:15.5

Exploitation, however, is rated as less likely for them. And then we have one

2:20.6

vulnerability, an elevation of bridge vulnerability in Asia Arc enabled Kubernetes Cluster Connect,

2:27.7

and that one was rated with a perfect 10.0 CVSS score.

2:36.3

Overall, nothing here that I would say sticks out as an immediate must patch.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.